First published: Fri Jun 16 2017(Updated: )
X-Pack 5.1.1 did not properly apply document and field level security to multi-search and multi-get requests so users without access to a document and/or field may have been able to access this information.
Credit: bressers@elastic.co
Affected Software | Affected Version | How to fix |
---|---|---|
Elastic | =5.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-8450 is rated as a medium severity vulnerability due to its potential for unauthorized information access.
To fix CVE-2017-8450, upgrade to a version of X-Pack higher than 5.1.1 where this issue has been addressed.
CVE-2017-8450 affects multi-search and multi-get requests within the X-Pack 5.1.1 version.
Organizations using X-Pack version 5.1.1 may be affected if they have implemented document and field level security.
CVE-2017-8450 is not an authentication bypass but allows unauthorized access to certain document and field data.